First published: Mon Jan 03 2022(Updated: )
The Booster for WooCommerce WordPress plugin before 5.4.9 does not sanitise and escape the wcj_delete_role parameter before outputting back in the admin dashboard when the General module is enabled, leading to a Reflected Cross-Site Scripting issue
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
Booster for WooCommerce | <5.4.9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2021-25000.
The affected software is Booster for WooCommerce WordPress plugin version up to 5.4.9.
The severity level of CVE-2021-25000 is medium (6.1 on the CVSS scale).
CVE-2021-25000 leads to a Reflected Cross-Site Scripting issue in the admin dashboard.
Yes, the fix for CVE-2021-25000 is to update the Booster for WooCommerce WordPress plugin to version 5.4.9 or higher.